sisdk-release
by Silabs.com
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6432 | Med | 0.00 | — | 0.00 | Jun 25, 2026 | Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage. | ||
| CVE-2026-4526 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was… | ||
| CVE-2026-47147 | Hig | 0.00 | 7.1 | 0.00 | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has… | ||
| CVE-2026-47145 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted. | ||
| CVE-2026-2815 | Hig | 0.00 | — | 0.00 | Jun 25, 2026 | Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys |
- risk 0.00cvss —epss 0.00
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
- risk 0.00cvss 6.5epss 0.00
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…
- risk 0.00cvss 7.1epss 0.00
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has…
- risk 0.00cvss 6.5epss 0.00
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.
- risk 0.00cvss —epss 0.00
Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys